<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>bafin Archives - MBE</title>
	<atom:link href="https://mbeconsulting.com/tag/bafin/feed/" rel="self" type="application/rss+xml" />
	<link>https://mbeconsulting.com/tag/bafin/</link>
	<description>Transforming Actuarial Performance</description>
	<lastBuildDate>Fri, 14 Jul 2023 09:20:20 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://mbeconsulting.com/wp-content/uploads/2025/03/cropped-2-32x32.png</url>
	<title>bafin Archives - MBE</title>
	<link>https://mbeconsulting.com/tag/bafin/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>VAIT: Germany’s Insurance IT Regulation</title>
		<link>https://mbeconsulting.com/euc-vait-compliance/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=euc-vait-compliance</link>
		
		<dc:creator><![CDATA[Andries Beukes]]></dc:creator>
		<pubDate>Wed, 11 Nov 2020 15:08:54 +0000</pubDate>
				<category><![CDATA[Actuarial Technology]]></category>
		<category><![CDATA[Actuarial Transformation]]></category>
		<category><![CDATA[bafin]]></category>
		<category><![CDATA[EUC]]></category>
		<category><![CDATA[VAIT]]></category>
		<guid isPermaLink="false">https://mbeconsulting.com/?p=4342</guid>

					<description><![CDATA[<p>Regulators recognise the risk posed by unmanaged end user computing (EUC) applications, such as spreadsheets. We discuss the challenges raised by complying with regulations such as VAIT, and how these can be resolved in collaboration with our EUC software partner, Apparity.</p>
<p>The post <a href="https://mbeconsulting.com/euc-vait-compliance/">VAIT: Germany’s Insurance IT Regulation</a> appeared first on <a href="https://mbeconsulting.com">MBE</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Around the world, regulators are recognising the magnitude of risk posed by unmanaged end user computing (EUC) applications, such as spreadsheets. Spreadsheet blunders can range from embarrassing to catastrophic. With billions in the balance, it’s no wonder that orders to prevent them are now coming from the top.</p>



<p class="wp-block-paragraph">This is especially relevant to the insurance sector. The financial security of millions of policyholders depends on the rigour with which models are managed. A manual, ad hoc approach is simply not good enough anymore, and it seems that the authorities agree.</p>



<hr class="wp-block-separator has-css-opacity is-style-default"/>



<h2 class="wp-block-heading"><strong>What is VAIT &amp; Who Does it Apply To?</strong></h2>



<p class="wp-block-paragraph">In 2018, Germany’s Federal Financial Supervisory Authority, BaFin, issued the&nbsp;<a href="https://www.bafin.de/SharedDocs/Veroeffentlichungen/EN/Meldung/2018/meldung_181120_veroeffentlichung_vait_englisch_en.html" target="_blank" rel="noreferrer noopener"><strong>Versicherungsaufsichtliche Anforderungen an die IT, or VAIT</strong></a>, requirements. VAIT sets out requirements relating to information security and information technology for the insurance industry.</p>



<p class="wp-block-paragraph">VAIT applies to all undertakings subject to supervision in accordance with section 1(1) of the German&nbsp;<a href="https://www.bafin.de/EN/DieBaFin/AufgabenGeschichte/Versicherungsaufsicht/versicherungsaufsicht_node_en.html" target="_blank" rel="noreferrer noopener"><strong>Insurance Supervision Act, Versicherungsaufsichtsgesetz (VAG)</strong></a>. It also applies to any insurance group with undertakings in other EU or European Economic Area states for which BaFin is the group supervisor.</p>



<h2 class="wp-block-heading"><strong>EUC-Specific Requirements</strong></h2>



<p class="wp-block-paragraph">VAIT includes dedicated requirements for end user computing (EUC) applications. Points 14, 15, 18 and 42 to 57 of the VAIT regulations are specified as applying to EUC applications. At a high level, these requirements may be grouped into four categories:</p>



<ol class="wp-block-list">
<li><strong>Inventory</strong><br>The ability to create and maintain a risk-based inventory of EUC applications.</li>



<li><strong>Version Control</strong><br>The ability to enforce and monitor varying levels of change/ release (version) control based on the risk classification of the EUC application.</li>



<li><strong>Change Management</strong><br>The ability to monitor EUC applications to identify unauthorized changes and facilitate approval workflows.</li>



<li><strong>Access Control</strong><br>The ability to control and limit access to critical EUC applications and those which contain confidential or personally identifiable information (PII).</li>
</ol>



<hr class="wp-block-separator has-css-opacity is-style-default"/>



<h2 class="wp-block-heading"><strong>How Apparity Helps</strong></h2>



<p class="wp-block-paragraph">MBE&#8217;s EUC software partner is Apparity. Our combined VAIT Compliance solution is designed to manage and control EUC applications within highly regulated industries, especially banking, insurance and the utility sector. Apparity’s standard functionality allows insurance companies to automate and evidence all of the EUC-specific requirements of VAIT.</p>



<h3 class="wp-block-heading"><strong>Inventory</strong></h3>



<ul class="wp-block-list">
<li><strong>Discovery Module</strong><br>Automatically create and maintain an inventory of EUC files, including key file details.</li>



<li><strong>Structural Complexity Algorithm</strong><br>Determine the complexity of each identified file using custom evaluation parameters.</li>



<li><strong>Registration</strong><br>Qualitative assessment of file impact to capture relevant data from file owners. Enables a risk-based inventory based on both complexity and impact.</li>



<li><strong>Connection Explorer</strong><br>Visually chart connections between discovered files. Provides a clearer understanding of upstream &amp; downstream dependencies.</li>
</ul>



<h3 class="wp-block-heading"><strong>Version Control</strong></h3>



<ul class="wp-block-list">
<li><strong>Versioning</strong><br>Automatically capture and track all file copies while allowing user comments to enable collaboration and audit trails.</li>



<li><strong>Version History</strong><br>View, export, and restore a file to a previous version or copy of a file.</li>



<li><strong>Zero Loss Fingerprinting</strong><br>Monitored files are always tracked, regardless of file save location or how it is named. Ensures there are never ‘lost copies’ of a file.</li>
</ul>



<h3 class="wp-block-heading"><strong>Change Management</strong></h3>



<ul class="wp-block-list">
<li><strong>Change Logs</strong><br>Real-time and in-session view of all critical changes made to a file. Filtering and sorting helps identify potential mistakes or unauthorized changes.</li>



<li><strong>Noise Filtering</strong><br>Users only see critical changes that are relevant to them configured against company EUC policy.</li>



<li><strong>Automated Review and Approval Workflow</strong><br>Ensures critical changes are properly signed off with included audit trails.</li>
</ul>



<h3 class="wp-block-heading"><strong>Access Control</strong></h3>



<ul class="wp-block-list">
<li><strong>File Access &amp; Modification Reports</strong><br>Track and log all users who update critical files.</li>



<li><strong>Unexpected Change Warnings</strong><br>Flag any changes made by non-Apparity users who might be outside the controls framework.</li>



<li>Apparity checks &amp; monitors against all&nbsp;<strong>Existing Access Control</strong>&nbsp;frameworks. Ensures access will never be granted to a file unless the user has access to the original file location.</li>



<li><strong>Automated PII identification</strong><br>Allows teams to understand which files have sensitive data that should not be accessible to broader audiences.</li>
</ul>



<p class="wp-block-paragraph">For further information on how MBE can support you with your EUC requirements please <a href="https://mbeconsulting.com/contact-mbe-actuarial-consulting/"><strong>get in touch</strong></a>. Additional information on the <a href="https://apparity.com/euc-resources/spreadsheet-euc-risk-blog/the-vait-is-over-germanys-insurance-it-regulation/"><strong>Apparity solution and how it helps with VAIT compliance can be found here</strong></a>.</p>
<p>The post <a href="https://mbeconsulting.com/euc-vait-compliance/">VAIT: Germany’s Insurance IT Regulation</a> appeared first on <a href="https://mbeconsulting.com">MBE</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
